The post Port3 Exploit Triggers Full Token Migration After Cross-Chain Vulnerability Exposes CATERC20 Weakness appeared on BitcoinEthereumNews.com. Port3 suffered a critical exploit today. A single validation flaw inside Nexa Network’s cross-chain CATERC20 token standard opened the door to unauthorized minting and a rapid price collapse. What followed was a full-scale breakdown of the token’s security model, a multi-address exploit, and now a complete token migration to stabilize the ecosystem. The incident is not just another hack. It’s a textbook case of how a boundary-condition bug buried inside a cross-chain implementation can wipe out an entire token economy once ownership is renounced. And Port3 now confirms it is reissuing the token, burning team tokens to neutralize excess supply, and migrating entirely to BNB Chain. Here’s the full breakdown. A Vulnerability Hidden in CATERC20 Opened the Door Port3 integrated Nexa Network’s CATERC20 standard to support multi-chain expansion. The goal was to power easy cross-chain messaging and token movement across several ecosystems. But CATERC20 carried a critical vulnerability inside its boundary-condition validation logic. Once ownership of the Port3 token contract was renounced, a move intended to increase decentralization, the validation function started returning a value of 0. That value matched the owner-verification condition, causing the ownership check to fail. As a result, the system treated unauthorized addresses as valid. The flaw did not appear in the CATERC20 audit report. Port3’s renounced-ownership status placed the token in the exact configuration where the vulnerability could be triggered. And once discovered, it opened the door to full unauthorized access. Incident Report: $PORT3 Hacker Attack PORT3 aimed to support the development of multiple chains, and therefore adopted @nexa_network’s cross-chain token solution, CATERC20. However, CATERC20 contained a boundary-condition validation vulnerability. After the token’s ownership… — Port3 Network (@Port3Network) November 23, 2025 The Hacker’s First Move: Registering a Fake Authorized Address The attacker located the authorization-verification bug inside the Port3 BSC-side contract and moved quickly. At… The post Port3 Exploit Triggers Full Token Migration After Cross-Chain Vulnerability Exposes CATERC20 Weakness appeared on BitcoinEthereumNews.com. Port3 suffered a critical exploit today. A single validation flaw inside Nexa Network’s cross-chain CATERC20 token standard opened the door to unauthorized minting and a rapid price collapse. What followed was a full-scale breakdown of the token’s security model, a multi-address exploit, and now a complete token migration to stabilize the ecosystem. The incident is not just another hack. It’s a textbook case of how a boundary-condition bug buried inside a cross-chain implementation can wipe out an entire token economy once ownership is renounced. And Port3 now confirms it is reissuing the token, burning team tokens to neutralize excess supply, and migrating entirely to BNB Chain. Here’s the full breakdown. A Vulnerability Hidden in CATERC20 Opened the Door Port3 integrated Nexa Network’s CATERC20 standard to support multi-chain expansion. The goal was to power easy cross-chain messaging and token movement across several ecosystems. But CATERC20 carried a critical vulnerability inside its boundary-condition validation logic. Once ownership of the Port3 token contract was renounced, a move intended to increase decentralization, the validation function started returning a value of 0. That value matched the owner-verification condition, causing the ownership check to fail. As a result, the system treated unauthorized addresses as valid. The flaw did not appear in the CATERC20 audit report. Port3’s renounced-ownership status placed the token in the exact configuration where the vulnerability could be triggered. And once discovered, it opened the door to full unauthorized access. Incident Report: $PORT3 Hacker Attack PORT3 aimed to support the development of multiple chains, and therefore adopted @nexa_network’s cross-chain token solution, CATERC20. However, CATERC20 contained a boundary-condition validation vulnerability. After the token’s ownership… — Port3 Network (@Port3Network) November 23, 2025 The Hacker’s First Move: Registering a Fake Authorized Address The attacker located the authorization-verification bug inside the Port3 BSC-side contract and moved quickly. At…

Port3 Exploit Triggers Full Token Migration After Cross-Chain Vulnerability Exposes CATERC20 Weakness

2025/11/24 16:41

Port3 suffered a critical exploit today. A single validation flaw inside Nexa Network’s cross-chain CATERC20 token standard opened the door to unauthorized minting and a rapid price collapse.

What followed was a full-scale breakdown of the token’s security model, a multi-address exploit, and now a complete token migration to stabilize the ecosystem.

The incident is not just another hack. It’s a textbook case of how a boundary-condition bug buried inside a cross-chain implementation can wipe out an entire token economy once ownership is renounced. And Port3 now confirms it is reissuing the token, burning team tokens to neutralize excess supply, and migrating entirely to BNB Chain.

Here’s the full breakdown.

A Vulnerability Hidden in CATERC20 Opened the Door

Port3 integrated Nexa Network’s CATERC20 standard to support multi-chain expansion. The goal was to power easy cross-chain messaging and token movement across several ecosystems.

But CATERC20 carried a critical vulnerability inside its boundary-condition validation logic.

Once ownership of the Port3 token contract was renounced, a move intended to increase decentralization, the validation function started returning a value of 0. That value matched the owner-verification condition, causing the ownership check to fail. As a result, the system treated unauthorized addresses as valid.

The flaw did not appear in the CATERC20 audit report.

Port3’s renounced-ownership status placed the token in the exact configuration where the vulnerability could be triggered. And once discovered, it opened the door to full unauthorized access.

The Hacker’s First Move: Registering a Fake Authorized Address

The attacker located the authorization-verification bug inside the Port3 BSC-side contract and moved quickly.

At 20:56:24 UTC, from address

0xb13A503dA5f368E48577c87b5d5AeC73d08f812E, the attacker executed a RegisterChains operation.

He registered his own address as an entity authorized to perform BridgeIn operations, the exact function needed to mint tokens during cross-chain transfers.

With that single move, the attacker became “trusted” by the contract due to the broken ownership check.

Minting 1 Billion Fake Tokens Through a Cross-Chain Fraud Path

Next, the attacker deployed a fake token on Arbitrum One. He initiated a cross-chain transaction that would normally go through CATERC20’s validation pipeline.

But the BSC-side Port3 contract failed to validate correctly.

Because the owner-verification condition returned 0, and because the attacker’s address was already registered, the transaction passed as legitimate. The contract proceeded to mint 1 billion PORT3 tokens.

Those tokens were immediately dumped across multiple DEXs, collapsing PORT3’s price from $0.03 to $0.0063 within minutes.

The attack didn’t stop there.

The same exploit was repeated using additional addresses, including:

0x7C2F4Bbda350D4423fBa6187dc49d84D125551fF

The result was a cascading liquidity shock that erased nearly all market value before operations were halted.

Port3 Responds: Exchange Coordination and Full Contract Migration

Within minutes of the exploit, Port3 moved to freeze movement across centralized platforms. Major exchanges were contacted to suspend deposits and withdrawals until the situation became clear..

Shortly after, Port3 announced the next steps: a full token migration with strict protection measures for users. The team emphasized that holders would not lose any tokens and that all legitimate balances before the exploit would be restored.

The Migration Plan: A Safeguard for All Users

Port3 outlined a detailed recovery process designed to restore stability across the ecosystem.

1. 1:1 Token Migration

A snapshot was taken at 20:56 UTC, immediately after the attack.

Every user holding PORT3 before that timestamp will receive a full 1:1 replacement.

The same guarantee applies to CEX balances once exchange coordination is finalized.

Port3 emphasized clearly: “Your tokens are SAFU.”

2. On-Chain Multi-Send Distribution

All addresses from the snapshot will receive their new tokens directly.

Port3 will use multi-send transactions of 200–500 tokens per tx, distributing to every affected wallet.

CEX migration details are still being finalized.

3. The New Token Lives Exclusively on BNB Chain

This was already hinted at in April, but now it becomes final.

All PORT3 liquidity on Ethereum was scheduled to migrate to BNB Chain. After the exploit, Port3 confirmed that the new token contract will be deployed only on BNB Chain going forward.

The move improves consistency, simplifies security management, and avoids repeating the multi-chain vulnerability path that enabled this attack.

4. Team Tokens Burned to Offset the Unauthorized Mint

The exploit created 1 billion unauthorized tokens during the minting attack.

To preserve total supply integrity, Port3 will burn 162,750,000 team tokens, fully neutralizing the excess and ensuring that the attacker receives nothing from the new contract.

This prevents inflation, restores supply balance, and closes the hole left by the exploit.

A Reset, Not a Shutdown, “The Team Is Here to Stay”

Port3 made one message clear:

  • The project is not going anywhere.

Despite the exploit, the team reiterated that development continues and that the ecosystem will recover stronger. The token migration is already underway, exchange reviews are happening in parallel, and trading will reopen once verification is complete.

Users were told to sit tight, avoid panic, and wait for the official restoration.

“All funds are SAFU.”

Conclusion: A Harsh Exploit, but a Full Rebuild Is Already in Motion

The Port3 exploit shows how fragile cross-chain token designs can be when a single validation pathway breaks. Once ownership was renounced, the CATERC20 flaw became catastrophic. A single boundary-condition error led to unauthorized registration, fake token minting, and a global price crash.

  • But the response has been fast, coordinated, and transparent.
  • The supply is being repaired.
  • The token is being migrated.
  • Users are protected.
  • And the attacker’s mint is being fully neutralized.

Port3 is moving forward, on a new contract, on a single chain, and with rebuilt tokenomics designed to ensure this never happens again.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/port3-exploit-triggers-full-token-migration-after-cross-chain-vulnerability-exposes-caterc20-weakness/

Piyasa Fırsatı
TokenFi Logosu
TokenFi Fiyatı(TOKEN)
$0.002619
$0.002619$0.002619
-5.96%
USD
TokenFi (TOKEN) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Trump-Backed WLFI Plunges 58% – Buyback Plan Announced to Halt Freefall

Trump-Backed WLFI Plunges 58% – Buyback Plan Announced to Halt Freefall

World Liberty Financial (WLFI), the Trump-linked DeFi project, is scrambling to stop a market collapse after its token lost over 50% of its value in September. On Friday, the project unveiled a full buyback-and-burn program, directing all treasury liquidity fees to absorb selling pressure. According to a governance post on X, the community approved the plan overwhelmingly, with WLFI pledging full transparency for every burn. The urgency of the move reflects WLFI’s steep losses in recent weeks. WLFI is trading Friday at $0.19, down from its September 1 peak of $0.46, according to CoinMarketCap, a 58% drop in less than a month. Weekly losses stand at 12.85%, with a 15.45% decline for the month. This isn’t the project’s first attempt at intervention. Just days after launch, WLFI burned 47 million tokens on September 3 to counter a 31% sell-off, sending the supply to a verified burn address. For World Liberty Financial, the buyback-and-burn program represents both a damage-control measure and a test of community faith. While tokenomics adjustments can provide short-term relief, the project will need to convince investors that WLFI has staying power beyond interventions. WLFI Launches Buyback-and-Burn Plan, Linking Token Scarcity to Platform Growth According to the governance proposal, WLFI will use fees generated from its protocol-owned liquidity (POL) pools on Ethereum, BNB Chain, and Solana to repurchase tokens from the open market. Once bought back, the tokens will be sent to a burn address, permanently removing them from circulation.WLFI Proposal Source: WLFI The project stressed that this system ties supply reduction directly to platform growth. As trading activity rises, more liquidity fees are generated, fueling larger buybacks and burns. This seeks to create a feedback loop where adoption drives scarcity, and scarcity strengthens token value. Importantly, the plan applies only to WLFI’s protocol-controlled liquidity pools. Community and third-party liquidity pools remain unaffected, ensuring the mechanism doesn’t interfere with external ecosystem contributions. In its proposal, the WLFI team argued that the strategy aligns long-term holders with the project’s future by systematically reducing supply and discouraging short-term speculation. Each burn increases the relative stake of committed investors, reinforcing confidence in WLFI’s tokenomics. To bolster credibility, WLFI has pledged full transparency: every buyback and burn will be verifiable on-chain and reported to the community in real time. WLFI Joins Hyperliquid, Jupiter, and Sky as Buyback Craze Spills Into Wall Street WLFI’s decision to adopt a full buyback-and-burn strategy places it among the most ambitious tokenomic models in crypto. While partly a response to its sharp September price decline, the move also reflects a trend of DeFi protocols leveraging revenue streams to cut supply, align incentives, and strengthen token value. Hyperliquid illustrates the model at scale. Nearly all of its platform fees are funneled into automated $HYPE buybacks via its Assistance Fund, creating sustained demand. By mid-2025, more than 20 million tokens had been repurchased, with nearly 30 million held by Q3, worth over $1.5 billion. This consistency both increased scarcity and cemented Hyperliquid’s dominance in decentralized derivatives. Other protocols have adopted variations. Jupiter directs half its fees into $JUP repurchases, locking tokens for three years. Raydium earmarks 12% of fees for $RAY buybacks, already removing 71 million tokens, roughly a quarter of the circulating supply. Burn-based models push further, as seen with Sky, which has spent $75 million since February 2025 to permanently erase $SKY tokens, boosting scarcity and governance influence. But the buyback phenomenon isn’t limited to DeFi. Increasingly, listed companies with crypto treasuries are adopting aggressive repurchase programs, sometimes to offset losses as their digital assets decline. According to a report, at least seven firms, ranging from gaming to biotech, have turned to buybacks, often funded by debt, to prop up falling stock prices. One of the latest is Thumzup Media, a digital advertising company with a growing Web3 footprint. On Thursday, it launched a $10 million share repurchase plan, extending its capital return strategy through 2026, after completing a $1 million program that saw 212,432 shares bought at an average of $4.71. DeFi Development Corp, the first public company built around a Solana-based treasury strategy, also recently expanded its buyback program to $100 million, up from $1 million, making it one of the largest stock repurchase initiatives in the digital asset sector. Together, these cases show how buybacks, whether in tokenomics or equities, are emerging as a key mechanism for stabilizing value and signaling confidence, even as motivations and execution vary widely
Paylaş
CryptoNews2025/09/26 19:12
Son of filmmaker Rob Reiner charged with homicide for death of his parents

Son of filmmaker Rob Reiner charged with homicide for death of his parents

FILE PHOTO: Rob Reiner, director of "The Princess Bride," arrives for a special 25th anniversary viewing of the film during the New York Film Festival in New York
Paylaş
Rappler2025/12/16 09:59
Bitcoin Peak Coming in 45 Days? BTC Price To Reach $150K

Bitcoin Peak Coming in 45 Days? BTC Price To Reach $150K

The post Bitcoin Peak Coming in 45 Days? BTC Price To Reach $150K appeared first on Coinpedia Fintech News Bitcoin has delivered one of its strongest performances in recent months, jumping from September lows of $108K to over $117K today. But while excitement is high, market watchers warn the clock is ticking.  History shows Bitcoin peaks don’t last forever, and analysts now believe the next major top could arrive within just 45 days, with …
Paylaş
CoinPedia2025/09/18 15:49